Of all the requirements in NIST SP 800-171, two tend to show up in conversations with defense subcontractors first: multifactor authentication and encryption. They are concrete, they are testable, and gaps are easy for an assessor to spot. They are also where many companies discover that a control they thought was in place has more exceptions than expected.
This article walks through how to approach both for a CUI environment. Always check the current requirement text and your assessment level for exact language.
Multifactor Authentication
What It Means in Practice
The requirements call for multifactor authentication for access to systems that process or store CUI, with particular attention to privileged accounts and network access. In plain terms, a password alone should not be enough to reach CUI.
Where to Apply It
Walk through every path to CUI and ask whether MFA is enforced:
- Sign-in to Microsoft 365 or other cloud services holding CUI
- Remote access such as VPN or virtual desktops
- Privileged and administrator accounts, including those used on servers and network gear
- Local sign-in to workstations or enclave systems, depending on your design
- Third-party applications that hold CUI
Common Gaps
- Exceptions granted to executives or specific users who found it inconvenient
- Service accounts and shared mailboxes that bypass MFA
- Legacy protocols that do not support modern authentication
- Backup access methods, such as recovery codes or text messages, that are weaker than the primary
- Break-glass administrator accounts with no monitoring
Document each exception and its compensating controls, and aim to eliminate them. Assessors will test.
Choose Methods Wisely
Authenticator apps and hardware keys are generally stronger than text message codes. Prefer phishing-resistant methods for administrators and anyone with broad access to CUI. Make sure staff know how to recover access if they lose a device, and protect that recovery process from social engineering.
Encryption
Data at Rest
CUI stored on laptops, servers, removable media, and backups should be protected with encryption. The standard calls for cryptography validated to federal standards, so check whether the products you use meet that expectation and how the vendor documents it. This detail matters in assessment, and it is easy to overlook.
Key places to check:
- Laptop and desktop drives, with recovery keys stored securely
- Servers and storage holding CUI
- USB drives and external media, ideally restricted or disallowed
- Mobile devices that access CUI
- Backups, including offsite and cloud copies
Data in Transit
CUI moving across networks, including the internet and internal links, should be protected. Verify:
- Email handling of CUI, including encrypted messaging options and rules about what may be sent
- Secure file transfer methods
- Encrypted remote access connections
- Wireless network encryption settings
Unencrypted file transfer tools and old protocols on internal servers are common findings.
Key Management
Encryption is only as good as the handling of keys. Decide who can access recovery keys, where they are stored, and how they are protected. Test recovery of an encrypted device before you need it.
Make Both Provable
Collect evidence as you implement:
- Screenshots or exports of MFA enforcement policies and user coverage reports
- Encryption status reports across devices
- Documentation of the cryptographic modules in use and their validation status
- Records of exceptions and approvals
- Procedures for key recovery and user lockouts
Link each item to the relevant requirement in your system security plan.
Plan for the Field
Field staff may sign in from weak connections and shared devices. Test how MFA prompts work in those conditions, and design the process so that CUI access is limited to controlled devices and people, rather than loosening controls to accommodate convenience.
Prioritize
If you are early in your journey, start with MFA on all accounts that can reach CUI, administrator accounts first, then confirm drive encryption on every endpoint in scope. These two steps reduce real risk and address visible requirements.
Ironfield Cyber helps defense subcontractors implement MFA and encryption that fit their environment, and document them for assessment. If you want a gap check on these two areas, we can run one with your team.